Content Injection T1659

Tactics: Initial Access, Command & Control

Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. These compromised online network channels may also be used to deliver additional payloads (i.e., Ingress Tool Transfer) and other data to already compromised systems.

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
DAVISRiskLevel3eq 2, ne 1CRITICAL
Muted3eq 3false
VulnerabilityType2eq 1, ne 1CODE_LEVEL

Top indicator values (5 distinct)

These values appear most often in rule predicates.

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Application

Domain: Application

Kusto 4 rules